DefenderHow-to

Onboarding macOS to Defender for Endpoint with Intune: profiles, app and onboarding package

The Intune deployment for Defender for Endpoint on Mac in the documented order: system extensions, Full Disk Access, network filter, background services, the app, the onboarding package, mdatp checks and fixes.

Onboarding a Mac to Defender for Endpoint is less about installing an app and more about getting macOS to trust it: system extensions, Full Disk Access, a network filter and background execution all need pre-approval, or users see prompts and the sensor runs half-blind. In this post I'll walk through the Intune deployment in the order Microsoft documents it, how to prove each piece landed, and what to do when it doesn't.

How this guide is organised: Prerequisites → Step-by-step → Verify → Tips and gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (5 steps: Approve the system extensions (settings catalog); Deploy the permission profiles (custom templates); Configure Defender's own settings; Publish the app; Deploy the onboarding package). 3. Verify. 4. Tips and gotchas. Toolbox: install.log, mdatp, General › Advanced features, Create › New policy, com.microsoft.wdav.epsext.1Prerequisites2Step-by-step3Verify4Tips and gotchas1Approve the systemextensions (settin…2Deploy thepermission profile…3ConfigureDefender's own se…4Publish the app5Deploy theonboarding packa…TOOLBOXinstall.logmdatpGeneral › Advanced featuresCreate › New policycom.microsoft.wdav.epsextHow this guide is organised: Prerequisites → Step-by-step → Verify → Tips and gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (5 steps: Approve the system extensions (settings catalog); Deploy the permission profiles (custom templates); Configure Defender's own settings; Publish the app; Deploy the onboarding package). 3. Verify. 4. Tips and gotchas. Toolbox: install.log, mdatp, General › Advanced features, Create › New policy, com.microsoft.wdav.epsext.1Prerequisites2Step-by-step1Approve the system extensions (settingscatalog)2Deploy the permission profiles (customtemplates)3Configure Defender's own settings4Publish the app5Deploy the onboarding package3Verify4Tips and gotchasTOOLBOXinstall.logmdatpGeneral › Advanced featuresCreate › New policycom.microsoft.wdav.epsext
At a glance: how this guide is organised · 5 steps · 5 key settings and tools

Prerequisites#

  • Licensing: Defender for Endpoint Plan 1 or Plan 2, or Defender for Business, plus Intune. Set up the Intune connection to Defender (Tenant administration › Connectors and tokens › Microsoft Defender for Endpoint in Intune, and the Microsoft Intune connection toggle under Settings › Endpoints › General › Advanced features in the Defender portal) if you want macOS compliance signals and the Defender portal policy option.
  • macOS versions: Microsoft supports the three most recent major releases. At the time of writing the prerequisites page lists macOS 27, 26 (Tahoe) and 15 (Sequoia); betas aren't supported, and new major versions are supported from release day. Re-check the list before a rollout, because it rolls forward every autumn.
  • Hardware: Intel 64-bit or Apple silicon, 1 GB of free disk space, and System Integrity Protection left on.
  • Network: direct, PAC, WPAD or static-proxy access to the Defender service URLs. Authenticated proxies and TLS inspection aren't supported.
  • Enrollment: Macs enrolled in Intune through Company Portal or Automated Device Enrollment, because every profile below deploys on the device channel.

Step-by-step#

Deploy the configuration profiles first, then the app, then the onboarding package. Microsoft calls out this order explicitly; reversing it is how you end up with permission prompts and unlicensed sensors.

Step 1: Approve the system extensions (settings catalog)#

In the Microsoft Intune admin center, go to Devices › Configuration › Create › New policy, platform macOS, profile type Settings catalog. Under System configuration › System extensions add:

  • Allowed System Extensions: com.microsoft.wdav.epsext and com.microsoft.wdav.netext, team identifier UBF8T346G9.
  • Allowed System Extension Types: Network and EndpointSecurity, same team identifier.

Step 2: Deploy the permission profiles (custom templates)#

Each of the following is a macOS Templates › Custom profile with Deployment channel set to Device channel, uploading a .mobileconfig file from Microsoft's Defender for Endpoint macOS configuration profile repository on GitHub:

ProfileSample fileWhat it does
Network filternetfilter.mobileconfigLets the network extension inspect traffic for EDR, network protection and web content filtering. Deploy exactly one network filter profile; several cause connectivity problems.
Full Disk Accessfulldisk.mobileconfigGrants Full Disk Access to Defender, the Endpoint Security extension and the DLP daemon, and stops users revoking it.
Background servicesbackground_services.mobileconfigRequired from macOS 13 so Defender's processes may run in the background.
Notificationsnotif.mobileconfigAllows Defender and Microsoft AutoUpdate to notify; set ShowInNotificationCenter to false to hide them.
Microsoft AutoUpdatecom.microsoft.autoupdate2.mobileconfigPins the update channel (Current, Preview or Beta). The sample is set to Current.
Accessibility, Bluetoothaccessibility.mobileconfig, bluetooth.mobileconfigOptional: needed for Endpoint DLP and for Bluetooth-based device control.

Step 3: Configure Defender's own settings#

Choose one of two routes. Either create endpoint security policies for macOS using the Microsoft Defender Antivirus and Endpoint detection and response templates (from the Endpoint security policies page in the Defender portal, or from Endpoint security in Intune), or deploy a custom profile containing Microsoft's recommended com.microsoft.wdav.xml. On the custom route the Configuration profile name must be exactly com.microsoft.wdav or Defender ignores it. This is where passive mode goes if a third-party antivirus stays on the Mac, and where network protection, device control and tamper protection are set. Note that the Intune EDR profile for macOS carries EDR settings such as device tags; the tenant association itself still comes from the onboarding package in step 5.

Step 4: Publish the app#

Go to Apps › All apps › Create and, under Microsoft Defender for Endpoint, select macOS. This built-in app type installs Microsoft Defender together with Microsoft AutoUpdate, which then keeps it current on the channel you pinned. Assign it to the same device group as the profiles.

Step 5: Deploy the onboarding package#

In the Defender portal, open Settings › Endpoints › Device management › Onboarding, select macOS, keep Streamlined connectivity, choose Mobile Device Management / Microsoft Intune and download the package. Unzip it, take intune/WindowsDefenderATPOnboarding.xml and deploy it as another custom profile on the device channel. This profile carries the tenant association and the licence; without it the app installs but reports no licence.

Verify#

  • Intune: each profile's Device and user check-in status report shows Succeeded, and the app shows Installed.
  • On the Mac: System Settings › General › Device Management lists the profiles including the onboarding profile, and the Defender shield appears in the menu bar. Full Disk Access granted by MDM is not shown under Privacy & Security, so don't look for it there.
  • Terminal:
Bash
mdatp health --field healthy
mdatp health --field licensed
mdatp health --field org_id
mdatp health --field real_time_protection_enabled
mdatp connectivity test
systemextensionsctl list

You want healthy and licensed true, your organisation ID populated, real-time protection enabled, every connectivity test passing, and both Microsoft extensions listed as activated and enabled. Then run Microsoft's antivirus detection test and EDR detection test, and confirm the device appears under Assets › Devices in the Defender portal with an Active sensor.

Tips and gotchas#

  • "No license found" or an empty org_id: the onboarding profile hasn't applied. Check its assignment and that you uploaded the Intune XML, not the Jamf plist from the same package.
  • Extensions not approved: the user sees a system extension prompt, or systemextensionsctl list shows them waiting for approval. Verify the settings catalog profile includes both bundle IDs and the team identifier, and that it reached the device before the app did.
  • Full Disk Access missing: real-time protection reports problems and scans skip files. Make sure the FDA profile is on the device channel and assigned to the device group, not only to users.
  • Network trouble after deployment: look for a second network filter profile from another product.
  • Logs: /Library/Logs/Microsoft/mdatp/install.log for install failures; sudo mdatp diagnostic create bundles diagnostics for support; mdatp health --details tamper_protection shows the effective tamper protection mode and its source.
  • Offboarding and removal: download the macOS offboarding package from Settings › Endpoints › Device management › Offboarding (offboarding packages expire seven days after download), deploy its profile, then remove the app. Intune can't uninstall Defender for Mac centrally because Apple doesn't provide a way; remove it from Applications or with sudo '/Library/Application Support/Microsoft/Defender/uninstall/uninstall'. If tamper protection is in block mode the uninstall is blocked by design, so relax it by policy first.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)